BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
New Codefinger Ransomware Abuses Amazon AWS to Encrypt S3 Buckets
/in General NewsThe Halcyon RISE Team has identified a new Codefinger ransomware campaign targeting Amazon S3 buckets. This attack leverages…
Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – Read More
Critical Aviatrix Controller Vulnerability Exploited Against Cloud Environments
/in General NewsAttackers are exploiting a critical vulnerability in Aviatrix Controller to execute arbitrary code in AWS cloud environments.
The post Critical Aviatrix Controller Vulnerability Exploited Against Cloud Environments appeared first on SecurityWeek.
SecurityWeek – Read More
AI, Web3 and Decentralization: Tech Trends Shaping 2025’s Altcoin Season
/in General NewsPrepare for the 2025 altcoin season: experts predict rising interest in altcoins like WorldCoin, driven by Web3, blockchain,…
Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – Read More
Zero-Day Vulnerability Suspected in Attacks on Fortinet Firewalls with Exposed Interfaces
/in General NewsThreat hunters are calling attention to a new campaign that has targeted Fortinet FortiGate firewall devices with management interfaces exposed on the public internet.
“The campaign involved unauthorized administrative logins on management interfaces of firewalls, creation of new accounts, SSL VPN authentication through those accounts, and various other configuration changes,” cybersecurity firm
The Hacker News – Read More
Malicious Kong Ingress Controller Image Found on DockerHub
/in General NewsA critical security breach in the software supply chain has been detected. An attacker accessed Kong’s DockerHub account…
Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – Read More
Illicit HuiOne Telegram Market Surpasses Hydra, Hits $24 Billion in Crypto Transactions
/in General NewsThe Telegram-based online marketplace known as HuiOne Guarantee and its vendors have cumulatively received at least $24 billion in cryptocurrency, dwarfing the now-defunct Hydra to become the largest online illicit marketplace to have ever operated.
The figures, released by blockchain analytics firm Elliptic, show that monthly inflows have increased by 51% since July 2024.
Huione Guarantee, part
The Hacker News – Read More
The ‘Largest Illicit Online Marketplace’ Ever Is Growing at an Alarming Rate, Report Says
/in General NewsHuione Guarantee, a gray market researchers believe is central to the online scam ecosystem, now includes a messaging app, stablecoin, and crypto exchange—while facilitating $24 billion in transactions.
Security Latest – Read More
Hitchhiker’s Guide to Managed Security
/in General NewsOver the past few years, we have had the opportunity to conduct several Purple Teaming exercises together with our customers. Some of the customers have their own Blue Team, others use an external provider for this service. Sometimes it is a mix, where an external company supports the internal Blue Team in its daily tasks.
Particularly after Purple Teaming exercises involving external providers, we often see a mismatch between the customer’s expectations and the service provided. This does not necessarily mean that the service provider has done a poor job, but rather that the customer expected something more, something different.
We have had many heated discussions in our office about how this mismatch between customer expectations and the actual service provided comes about. From these discussions, combined with our experience from our past Purple Teaming exercises, we compiled this blog post to share our take on how to prevent the most prevalent issues as early as possible.
Before we get into the details, we would like to point out that this blog is not intended to be a bashing of such service providers! On the contrary, we believe that these services are essential for companies that lack the size and capabilities to operate their own Blue Team. Rather, we want to turn a lose-lose situation into a win-win situation for both, the customer and the service provider.
No time to read this post? Download our one-pager PDF:
Where it all starts – Evaluation of a Service Provider
Nomen est omen?
As you may have noticed, in our introduction to this blog we just mentioned a “service”. The reason for this is that there are many different names for such a “service”. Here are some examples we have come across:
As far as we know, there is no clear definition of these terms and what they encompass, so we were never sure what to expect. It is probably fair to assume that customers feel the same way. So how can these services be compared and what can be expected?
In our experience, one of the key differentiators between various provider models is the scope of the underlying detection capabilities. There are mainly two types that we encountered:
Both types of service have their place. Services based solely on an EDR are more cost-effective, but lack the ability to implement complex custom detection rules. Also, additional existing security devices such as firewalls, web application firewalls, proxies, etc. may not be able to be integrated into such a solution, restricting the coverage for possible detections. Nevertheless, depending on the size, complexity and threat model of your environment, this type of service may be more than enough. The important thing is that you, as the customer, have a clear understanding of the provided detection capabilities.
Does it fit?
Now that you understand the potential detection capabilities that can be provided, the big question is whether it fits your environment or not. There are three main points to consider:
Threat Model
To choose the right service and service level, you need to understand your threat model. Is the main threat a ransomware attack or do you fear a more targeted attack on your infrastructure and users? Lies your main concern with the availability of your services or rather with the confidentiality of your data (or both)? What assets are crucial to your company’s ability to operate?
Depending on your threat model the necessary service might look different.
IT Infrastructure Coverage
As implied previously, an EDR-only approach may be sufficient for your environment and threat model. Still you need to check if the EDR solution can be installed on all your different operating systems. If a substantial part of your infrastructure is operated on Linux, but the EDR solution of your provider only runs on Windows, this could prove problematic. An other example might be that a provider offers extensive coverage of cloud infrastructures, but has little to no detection capabilities for on-premise systems.
However, if you have a more complex environment and critical assets to protect, you may need to consider further detection capabilities beyond an EDR solution.
Suppose you have a database server with sensitive customer data that is accessible through a web application. You want to know if someone has gained unauthorized access to the database and extracted this sensitive data. How hard can that be, right? Well, do you know which log files you need to build a detection logic for that?
The point is that writing custom detection logic is not a simple task. So if you require such use cases, the provided service must at least be able to ingest these logs. In the best case the service already provides such use cases that can be implemented or adapted to your environment.
Service Availability
We encountered many different service availability models during our Purple Teaming engagements:
Obviously these different models have different price tags attached, and usually more is better from a security perspective. However, the main point here is that the chosen model should fit your business model and your availability.
Lets assume you have chosen the 7×24 model. On a Saturday at 03:00, the external provider notices suspicious activities on one of your clients. They send you an email with the incident and the corresponding details. Will you see this email in time to benefit from the 7×24 model or will it be picked up only on Monday morning? You may have set up an on-call service and be able to react accordingly, but these things are your responsibility as a customer. Maybe a 5×10 model would better fit your business model and availability?
Communication is Key
In addition to the detection capabilities discussed above, another major trip wire is the communication between the service provider and the customer. Let us give you a few examples.
During a Purple Team we typically execute a known malware on a provided test client. This triggers the EDR (or whatever anti-virus solution is in place) to block and/or quarantine the malware on the host. Top! But often service providers do not open an incident for such an alert. Why not? Well, sometimes the reason given to us is that the malicious software has been successfully blocked, so the customer does not need to take any action. Another reason could be that the alert does not reach a required severity threshold. For example, it is a low rated alert and only high and critical alerts are handled by the service provider. However, you as a customer might still want to know about such incidents, since malware on a client could be an indication of something bigger happening.
In another instance, the customer might have installed some new servers for us to run our tests on, but has forgotten to report these systems to the service provider. So they were never correctly on-boarded and alerts were never received.
What this shows is that it is vital that communication works in both directions and that everyone knows what to expect and where the responsibilities lie.
Clearly define which alerts, incidents etc. will be handled by the service provider and which incidents are forwarded to you. Furthermore, clearly define the responsibilities for both parties, e.g. reporting of new devices, users and systems.
Lastly, it also should be ensured that the chosen communication channels fit your environment and enable you as a customer to react to incidents with as little delay as possible. Also think about fallback solutions and escalation chains in case of emergencies.
Incident Happened – Now What?
Let’s stick with the above example of malware running on the test client. You have clearly defined that you want an incident for such an alert, and the service provider will open one for you.
But what kind of information will the service provider present to you? Will it just be the auto-generated alert from the EDR solution? Will they add context to the auto-generated alert? Will they provide you with recommended remediation steps? Will they perform an initial analysis and provide this information to you?
It is important to understand that there is no golden rule here. But, whatever the details of the incident look like, it should meet your needs to quickly and correctly understand the incident and the associated risk so that you can decide on an adequate response. If you operate your own internal Blue Team and your employees have a SOC background, not much additional information might be required. On the other hand, if incidents raised by your provider are handled by your regular service desk for example, they might need additional guidance.
You may also want the service provider to be able to take immediate action, such as isolating a client. Be sure to check what reactions a service provider can offer, and weigh the pros and cons carefully.
Transparency Creates Trust
If you need custom or extended use cases, or if the service provider brings their own, it is important to understand how these use cases are implemented. This does not mean that you need access to the underlying query and detection logic itself, but rather the documentation of such use cases. This helps you understand whether a given use case even makes sense in your environment. In addition, in the event of an incident, this information may be critical to understanding the incident.
You probably also want to be able to track the decisions and assessments made by the service provider for your alerts and incidents. For example, you may want to know why a certain alert was classified as false-positive. Most service providers provide this to their customers in the form of a dashboard. Check that all the information you need is available and that the portal meets your needs.
Implementation Hell
Once you have evaluated a service provider, it is time to start the integration and on-boarding process. This is one of the phases where we, as a Purple Team, identify the most technical pitfalls. Here are the ones we encounter most often.
Missing Log Collection
A very common problem is that not all log sources are on-boarded into the service. Sometimes the agent is not installed on a specific system, or a particular log source was not considered to be implemented.
An accurate inventory of your assets will help you keep track of what is missing. Regularly checking your inventory and the sources you have on-boarded will also help you to reduce drift.
Missing Tailoring for Customer Environment
Custom use cases can add value to your detection capabilities. Unfortunately, we often find that these use cases do not work as expected in our customers’ environments. This is mostly because the use cases are not tailored to the customer’s environment.
For example, if a use case requires a certain threshold to be reached, say a login was attempted on 100 accounts in a short period of time, but there are only <100 accounts in the customer environment, this use case may actually never be triggered.
Another example might be a use case to detect if a local administrator is used on a client. If the use case is based on a specific user name, e.g. “administrator”, but the user has been renamed to “admin” in the customer environment, this use case will never be triggered.
It is therefore vital that all use cases are challenged and tailored to your environment.
Unclear Exception Handling
In any reasonably large environment, exceptions will quickly accumulate, especially during the integration phase. It is easy to lose track of what has been excluded from which use case, for what reason, and so on. Exceptions can also be set too broadly, which can render a use case ineffective.
Having a clear process for how exceptions are handled and documented is critical to keeping track.
Missing Use Case Testing
Far too often we come across use cases which have never been tested in the customer environment. They might work in a lab where they have been developed but for what ever reason they might fail to trigger elsewhere.
During the service acceptance test, each use case should be tested and verified first. But don’t stop there. Ideally, use cases should be tested regularly. If possible, automatically as long as it is in your production environment.
Unclear Documentation
In a Purple Team engagement we often have a lot of questions about use cases and general implementation etc. Unfortunately, it is sometimes difficult to get an informed answer to our questions. Either the right person is not available or it is simply unknown and requires a configuration review and deeper investigation.
Having an up-to-date and clear documentation of your implementation, use cases, exceptions etc. will help you to understand if something is missing or unclear. Don’t put documentation off for too long.
Continuous Improvement
When the integration project is complete, and you have avoided all the pitfalls and completed the documentation, you can be proud of yourself! Well done!
Don’t take too much of a break, though. Your IT environment is about to change. It could be through replacements, updates or new additions of tools and other gadgets. Maybe you decide to get rid of a substantial amount of on-premise systems and move your services into the cloud. Keeping up with these changes can be a challenge. The threat landscape will also change in the future, and you will need to adapt to the new risks.
So getting into the habit of questioning your existing solution is a good thing and should be done regularly.
Final Thoughts
We hope to have highlighted the most common pitfalls we encounter in our Purple Team exercises and how to avoid them. Running a service like this is no easy task and there are many more things that can go wrong. Have you come across any of these on your journey? Or are we missing something important? Please leave a comment, we are always keen to discuss.
Authors
This article was co-written by Alex Joss and Felix Aeppli.
Compass Security Blog – Read More
How Barcelona became an unlikely hub for spyware startups
/in General NewsBarcelona’s mix of affordable cost of living and quality of life has helped create a vibrant startup community — and become a hotbed for the creation of surveillance technologies.
© 2024 TechCrunch. All rights reserved. For personal use only.
Security News | TechCrunch – Read More
Infostealer Infections Lead to Telefonica Ticketing System Breach
/in General NewsInfostealer malware allowed threat actors to compromise Telefonica employees’ credentials and access the company’s internal ticketing system.
The post Infostealer Infections Lead to Telefonica Ticketing System Breach appeared first on SecurityWeek.
SecurityWeek – Read More